Lucene search

K
cveQualcommCVE-2017-18317
HistoryNov 28, 2018 - 3:29 p.m.

CVE-2017-18317

2018-11-2815:29:00
CWE-20
qualcomm
web.nvd.nist.gov
39
cve
2017
18317
modem
sim lock
sim kill
bypass
manipulation
system
deactivation flow
snapdragon automobile
snapdragon mobile
msm8996au
sd 410
sd 412
sd 820
sd 820a
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

12.6%

Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivation flow sequence in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU,SD 410/12,SD 820,SD 820A.

Affected configurations

Nvd
Node
qualcommmsm8996au_firmwareMatch-
AND
qualcommmsm8996auMatch-
Node
qualcommsd_410_firmwareMatch-
AND
qualcommsd_410Match-
Node
qualcommsd_412_firmwareMatch-
AND
qualcommsd_412Match-
Node
qualcommsd_820_firmwareMatch-
AND
qualcommsd_820Match-
Node
qualcommsd_820a_firmwareMatch-
AND
qualcommsd_820aMatch-
VendorProductVersionCPE
qualcommmsm8996au_firmware-cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:*
qualcommmsm8996au-cpe:2.3:h:qualcomm:msm8996au:-:*:*:*:*:*:*:*
qualcommsd_410_firmware-cpe:2.3:o:qualcomm:sd_410_firmware:-:*:*:*:*:*:*:*
qualcommsd_410-cpe:2.3:h:qualcomm:sd_410:-:*:*:*:*:*:*:*
qualcommsd_412_firmware-cpe:2.3:o:qualcomm:sd_412_firmware:-:*:*:*:*:*:*:*
qualcommsd_412-cpe:2.3:h:qualcomm:sd_412:-:*:*:*:*:*:*:*
qualcommsd_820_firmware-cpe:2.3:o:qualcomm:sd_820_firmware:-:*:*:*:*:*:*:*
qualcommsd_820-cpe:2.3:h:qualcomm:sd_820:-:*:*:*:*:*:*:*
qualcommsd_820a_firmware-cpe:2.3:o:qualcomm:sd_820a_firmware:-:*:*:*:*:*:*:*
qualcommsd_820a-cpe:2.3:h:qualcomm:sd_820a:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Snapdragon Automobile, Snapdragon Mobile",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "MSM8996AU,SD 410/12,SD 820,SD 820A"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2017-18317